ancient-wolf-19325
09/03/2024, 11:35 AMuserAuth.openId.clientId and appAuth.thirdPartyConfig.flyteClient.clientId.
2. Verify Scopes: Ensure that the scopes requested by Flyte are correctly configured in your IdP. The scopes are specified in userAuth.openId.scopes and appAuth.thirdPartyConfig.flyteClient.scopes.
3. Configuration Example: Here is an example configuration for Flyte with Keycloak as the IdP:
userAuth:
openId:
baseUrl: https://<keycloak-domain>/auth/realms/<realm>
clientId: flytectl
scopes:
- profile
- openid
- offline_access
appAuth:
thirdPartyConfig:
flyteClient:
clientId: flytectl
redirectUri: http://localhost:53593/callback
scopes:
- offline
- all
4. Error Logs: Check the error logs for more details. For example, the error invalid_scope indicates that the requested scopes do not match those configured in the IdP (source).
Would you like more detailed steps or further assistance with a specific part of the configuration?
Sources:
- https://github.com/flyteorg/flyte/issues/4955
- https://github.com/flyteorg/flyte/issues/2606
Slack Link
https://flyte-org.slack.com/archives/CP2HDHKE1/p1725363291.380469 👍 0 button 👎 0 button 💡 Hint: Mention @runllm in the thread for followups.